Researchers have spotted Locky ransomware infections emanating from the Necurs botnet via Word attachments using a DDE technique that Microsoft says is an Office feature and does not merit a security patch. Microsoft has replaced DDE with the Object Linking and Embedding toolkit, but it has not discontinued support for DDE because Office still supports legacy documents that use the feature. DDE allows a user to pull data from one document and inject it into a second, such as a when a sales report is opened in Word.
Source: https://threatpost.com/necurs-based-dde-attacks-now-spreading-locky-ransomware/128554/